NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4248 most downloaded on Packagist
Handles drag and drop of files for you.
Last release 10 days ago
27 Sep 2026
Ships unpredictably
gaps range from 8 days to 4.8 years
Nearly every release is documented
notes for 18 of 18 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
19 releases · first in 2021
One column per quarter.
### Patch Changes - #2380 `88901b7` - Fix binaryBody uploads sending the original file instead of the transformed one. resizeWidth, resizeHeight and a
#2380 88901b7 - Fix binaryBody uploads sending the original file instead of the transformed one. resizeWidth, resizeHeight and any custom transformFile were silently ignored, so an unresized image went to the server. Chunked and form-data uploads were unaffected.
#2379 eae9121 - Fix cancelling an upload while transformFile is still running. The file had no xhr yet, so it was grouped with every other file that had not started and the whole queue was cancelled with it — and the file itself was still sent once the transform finished.
### Patch Changes - #2377 `0b302ee` - Stop destroy() removing a different instance. Dropzone.instances.splice(indexOf(this), 1) dropped the last entry
#2377 0b302ee - Stop destroy() removing a different instance. Dropzone.instances.splice(indexOf(this), 1) dropped the last entry whenever indexOf returned -1 — calling destroy() twice was enough — evicting an unrelated live Dropzone from the registry.
#2377 dc5d7bf - Set enctype="multipart/form-data" on a form again. init() compared tagName against lower-case "form", which never matches, so the attribute was never set. Only affects forms that are also submitted natively; the XHR upload is unchanged.
file.xhr only holds the request that started last, so cancelling a chunked upload running with parallelChunkUploads aborted that one request and left
#2371 536d94a - Fix cancelUpload leaving parallel chunks uploading.
file.xhr only holds the request that started last, so cancelling a chunked upload running with parallelChunkUploads aborted that one request and left every other in-flight chunk streaming to the server — burning the user's bandwidth and writing orphaned chunks for a file the UI already showed as canceled.
Every chunk keeps its own request, so cancelUpload now aborts all of the ones still running. Uploads that are not chunked are unaffected.
#2372 a1a67df - Fix emit skipping a listener when another one removes itself.
emit walked the live callback array, so a listener that called off for itself — the usual shape of a one-shot listener, and of teardown code — spliced the array out from under the loop and the listener registered right after it never ran. emit now iterates over a snapshot.
One consequence worth knowing about: a listener registered from inside another listener no longer runs during that same emit, it runs from the next one. That is what Node's EventEmitter does, and it is the only way to keep the removal case correct.
#2370 0e3625d - Fix the thumbnail queue deadlocking when a file cannot be read.
createThumbnail only listened for FileReader's load event. A file that had been moved, locked by another process, or was otherwise unreadable since it was dropped fires error instead, so the callback was never invoked and _processThumbnailQueue kept its lock forever: no file added afterwards got a thumbnail, and with resizeWidth/resizeHeight or a transformFile that uses createThumbnail, the upload never started either.
The read error now reaches the callback the same way an undecodable image already did, so the file gets dictThumbnailError and the queue moves on.
DropzoneThumbnailCallback says what it has always done, too: its first argument is string | Event, the error event standing in for the data URL when no thumbnail could be produced. That also fixes displayExistingFile, which used to emit that event as a thumbnail when the image URL failed to load, leaving the preview with img.src set to "[object Event]".
This only affects you if you were importing dropzone/src/dropzone.scss directly rather than the built CSS. Import dropzone/src/dropzone.css instead, o
#2362 07d3876 - Drop the sass dependency. The stylesheets are plain CSS now, and dist/dropzone.css and dist/basic.css are unchanged in what they do: the output was compared declaration by declaration, and every difference is a value-level equivalence the minifier applies, such as padding: 20px 20px collapsing to padding: 20px.
This only affects you if you were importing dropzone/src/dropzone.scss directly rather than the built CSS. Import dropzone/src/dropzone.css instead, or the compiled dropzone/dist/dropzone.css.
If you installed @types/dropzone, uninstall it: it is stuck at 5.7.9 and describes the v5 API, so it will now conflict with — and is less accurate tha
#2361 4724f39 - Ship TypeScript types. The library is now written in TypeScript and the package carries its own declarations, so dropzone is typed from its own source.
If you installed @types/dropzone, uninstall it: it is stuck at 5.7.9 and describes the v5 API, so it will now conflict with — and is less accurate than — the types shipped here.
Dropzone.prototype.Emitter is now Dropzone.Emitter. It was undocumented and described in the source as being exposed for tests, so this is unlikely to affect you; if you reached for it, the class is in the same place under the shorter name.
4724f39 - Give each dropzone its own thumbnail queue. It lived on the prototype, so every dropzone on a page shared one: queuing a thumbnail on one was visible from the others, and they rendered from a single queue guarded by a single lock. Only pages with more than one dropzone were affected.### Patch Changes - #2355 `07a1347` Thanks @enyo! - Point homepage at https://www.dropzone.dev/. It referenced /js, a route that only ever redirected
#2355 07a1347 Thanks @enyo! - Point homepage at https://www.dropzone.dev/. It referenced /js, a route that only ever redirected to the front page and no longer exists, so the homepage link on npm was a 404.
#2353 bb5af51 Thanks @enyo! - CODE_OF_CONDUCT.md is no longer part of the published package. It stays in the repository where GitHub looks for it, but the library now lives in packages/dropzone and npm can only pack files from inside that directory. Nothing else about the package changed.
This changes when the event fires. Reading a folder is asynchronous, so on browsers that support folder drops — all of them — addedfiles is now emitte
#2351 ee82380 Thanks @enyo! - addedfiles now reports the files found inside a dropped folder. It previously received e.dataTransfer.files, which holds the folder entries rather than their contents, so anyone counting dropped files got the wrong answer for folders.
This changes when the event fires. Reading a folder is asynchronous, so on browsers that support folder drops — all of them — addedfiles is now emitted once the walk finishes, after the individual addedfile events, instead of synchronously at the end of the drop handler. Listeners still receive the event; only the timing moves.
Also adds an emptyfolder event, emitted with the folder's path when a dropped folder turns out to contain nothing at all.
#2348 f0697ee Thanks @enyo! - parallelChunkUploads: true now starts at most parallelUploads chunks at a time rather than every chunk of the file at once. Pass a number to set a different limit, or Infinity to restore the previous behaviour.
#2349 8a8b449 Thanks @enyo! - Add resizeTransparencyFill, the color shown through transparent parts of a resized image. A transparent PNG resized to image/jpeg previously came out with black where it used to be see-through; set this to "#fff", or any CSS color, for a background instead. Defaults to null, which keeps the current behavior.
d3a9221 Thanks @enyo! - Reword the default dictMaxFilesExceeded message from "You can not upload any more files." to "You cannot upload any more files."
#2350 9b5015b Thanks @enyo! - Give the hidden file input an aria-label, so accessibility auditors stop reporting it as an unlabelled input. This does not change anything for screen reader users: browsers leave visibility: hidden elements out of the accessibility tree entirely, and the .dz-button carrying dictDefaultMessage remains the control they interact with.
#2352 b24f8cc Thanks @enyo! - Associate the hidden file input with its form. The input is appended to hiddenInputContainer (the body by default), so it sits outside the form it belongs to and several dropzones on one page produce indistinguishable inputs. It now carries a form attribute when the dropzone is a form, or sits inside one, and that form has an id. The input has no name, so this does not change what a native submit sends — but it does mean the input now appears in form.elements.
4e13aab Thanks @enyo! - Vendor just-extend into the source and drop the dependency. Dropzone now installs with no dependencies at all; the option merging behaviour is unchanged.
`b32d746` Thanks @filip-kinsky! - Emit an error instead of a broken thumbnail when a file claims an image type but cannot be decoded. The new dictThum
b32d746 Thanks @filip-kinsky! - Emit an error instead of a broken thumbnail when a file claims an image type but cannot be decoded. The new dictThumbnailError option holds the message.94a0656 Thanks @AJHoeh! - Coerce chunkSize to a number before computing chunk boundaries. When the option arrived as a string, every chunk after the first was sliced from the wrong offset and the uploaded file was silently corrupted.
85c5c2a Thanks @enyo! - Stop preview thumbnails from being dragged back into the dropzone, which added the same file a second time under a generated name.
4762df8 Thanks @Forceu! - Send a single chunk for zero byte files instead of hanging. With forceChunking enabled, an empty file produced a chunk count of zero, so nothing was ever uploaded.
The 6.0.0 line is now stable. There are no API changes since 6.0.0-beta.2 — see the 6.0.0-beta.1 notes below for the breaking changes in this major ve…
The 6.0.0 line is now stable. There are no API changes since 6.0.0-beta.2 —
see the 6.0.0-beta.1 notes below for the breaking changes in this major
version.
@swc/helpers is no longer a dependency. just-extend is now the only one.Add binaryBody support (thanks to @patrickbussmann and @meg1502).
binaryBody support (thanks to @patrickbussmann and @meg1502).
test/test-sites/2-integrations.Fix incorrect resize method used for creating thumbnails of existing files (thanks to @gplwhite)
Handle xhr.readyState in the submitRequest function and don't attempt to send if it's not 1 (OPENED). (thanks to @bobbysmith007)
xhr.readyState in the submitRequest function and don't attempt to
send if it's not 1 (OPENED). (thanks to @bobbysmith007)Fix the way upload progress is calculated when using chunked uploads. (thanks to @ckovey)
Properly handle when timeout is null or 0
Fix custom event polyfill for IE11
Revert dist/min/*.css files to be named dist/min/*.min.css.
dist/min/*.css files to be named dist/min/*.min.css.Rename blacklistedBrowsers to blockedBrowsers (but still accept blacklistedBrowsers for legacy).
blacklistedBrowsers to blockedBrowsers (but still accept
blacklistedBrowsers for legacy).package.json.Prevent hidden input field from getting focus (thanks to @sinedied)
maxFilesize (thanks to @alxndr-w)WARNING: This release had issues because the .js files couldn't be imported as AMD/CommonJS packages properly. The standalone version worked fine thou
disablePreviews option.Your coding agent can read these notes before it upgrades. Set up the MCP server →